TrellixNetwork Security

    Network Detection and Response

    Finds the threat in the 95% of traffic that is encrypted — without decrypting it.

    Ninety-five percent of network traffic is now encrypted, and most SOCs ignore two-thirds of their alerts to alert fatigue. Trellix Network Detection and Response (NDR) cuts through both problems: it detects threats inside encrypted traffic without decryption and uses a Risk Aggregation Framework to surface only the threats that pose genuine business risk. Faltrox runs the console and the investigations so the signal reaches a human.

    Overview

    What Network Detection and Response is

    Trellix Network Detection and Response (NDR) transforms network security through intelligent risk prioritisation. Two problems break most network security today: 95% of traffic is now encrypted, creating blind spots deep packet inspection cannot see, and SOCs ignore the majority of their alerts to fatigue. NDR answers both — it detects threats inside encrypted traffic without decryption, and its Risk Aggregation Framework surfaces only the threats that pose genuine business risk.

    It covers on-premises, cloud, and hybrid infrastructure through one platform, with native virtual sensors for AWS, Azure, and GCP and integrations reaching OT/ICS and IoT. Multilayered detection spans all 14 MITRE ATT&CK tactics, Active NDR contains threats in real time, and Trellix Wise GenAI turns junior analysts into effective threat hunters. Faltrox runs the console and the investigations so the signal reaches a human.

    Coverage

    What it protects

    The platforms, threats, and surfaces this product is built to defend.

    01

    On-Premises Networks

    Unified visibility and detection across the corporate network from data centre to branch.

    02

    AWS, Azure & GCP

    Purpose-built virtual sensors give native monitoring across multicloud environments.

    03

    OT/ICS & IoT

    Integrations reach operational technology and IoT so those surfaces are not a blind spot.

    04

    Encrypted Traffic

    JA3/JA3S fingerprinting and behavioural analysis find threats in encrypted flows without decryption.

    05

    Lateral Movement

    Attack Path Discovery visualises how an attacker could escalate and move through the infrastructure.

    06

    Evasive Threats

    Catches DNS tunnelling, ICMP exfiltration, newly registered domains, and SSL anomalies signatures miss.

    How it works

    The mechanism

    How the product moves from signal to protected state, step by step.

    1. 01

      See

      Sensors across physical, virtual, and cloud environments deliver unified visibility, including native monitoring of AWS, Azure, and GCP.

    2. 02

      Detect

      Behavioural analytics, machine learning, and threat intelligence detect across all 14 MITRE ATT&CK tactics, including inside encrypted traffic.

    3. 03

      Prioritise

      The Risk Aggregation Framework weighs asset criticality, vulnerability exposure, and ATT&CK tactics to surface only genuine business risk.

    4. 04

      Investigate

      Trellix Wise automatically analyses alerts, maps techniques, and recommends remediation, with full packet capture for forensic depth.

    5. 05

      Contain

      Active NDR blocks traffic, isolates systems, and coordinates with integrated tools to stop the attack in real time.

    Capabilities

    Key capabilities

    Encrypted Traffic Analysis

    JA3/JA3S fingerprinting, certificate reputation, and behavioural analysis reveal threats hiding in encrypted communications without decryption — keeping privacy compliance while closing the biggest modern blind spot.

    Risk Aggregation Framework

    Combines asset criticality, vulnerability data, and MITRE ATT&CK tactics to automatically prioritise threats, so analysts see genuine business risk rather than a flat stream of generic alerts.

    Attack Path Discovery

    Visualises potential attack vectors by combining vulnerability data with network topology, showing how an attacker could escalate and move laterally — so critical vulnerabilities get fixed before exploitation.

    Multilayered Kill-Chain Detection

    Behavioural analytics, machine learning, and threat intelligence detect across all 14 MITRE ATT&CK tactics, catching DNS tunnelling, ICMP exfiltration, newly registered domains, and SSL anomalies signatures miss.

    Active NDR

    Immediate containment through automated response — traffic blocking, system isolation, and coordinated action with integrated security tools to stop an attack in real time.

    Hybrid & Multicloud Visibility

    Purpose-built virtual sensors provide native monitoring for AWS, Azure, and GCP alongside on-premises, unifying visibility across IT, OT/ICS, IoT, and cloud on one platform.

    Trellix Wise Investigation

    GenAI automatically analyses alerts, maps techniques to ATT&CK, identifies affected entities, and recommends remediation — turning junior analysts into effective threat hunters.

    Advanced Forensics

    Complete packet capture and metadata retention with timeline reconstruction and attack visualisation, so an investigation understands full scope and prevents recurrence.

    Specifications

    Technical detail

    Sensor Throughput
    NDR Sensor (NX Evolution) up to 40 Gbps; IPS "NDR Ready" up to 240 Gbps
    Cloud Sensors
    Native virtual sensors for AWS, Azure, GCP
    Detection Coverage
    All 14 MITRE ATT&CK tactics
    Deployment
    Physical, virtual, and cloud
    Add-ons
    Full Packet Capture, IVX dynamic file analysis, Attack Path Discovery; integrations with SWG, firewalls, proxies, OT platforms

    Works with

    Part of the platform

    Trellix products this pairs with, and the Faltrox services that operate it.

    Delivery

    You buy the outcome, not the console

    Managed by Faltrox

    Faltrox licenses, deploys, and tunes Trellix Network Detection and Response for your environment, then runs it as part of a managed service, so you get the protection without staffing another security console.

    See the service

    FAQ

    Common questions

    01How does it detect threats in encrypted traffic without decrypting it?

    Through JA3/JA3S fingerprinting, certificate reputation analysis, and behavioural analysis of the encrypted flow — the metadata and behaviour of the connection, not its contents. That keeps you compliant with privacy requirements while still seeing threats that deep packet inspection cannot.

    02Our SOC already ignores most of its alerts. How is this different?

    That is the problem the Risk Aggregation Framework targets. Instead of scoring every event equally, it weights asset criticality, vulnerability exposure, and ATT&CK tactics to surface only genuine business risk. The goal is fewer, higher-fidelity alerts a human actually acts on.

    03Does it cover cloud and OT, or just the corporate network?

    Both. Virtual sensors give native monitoring for AWS, Azure, and GCP, and it integrates with OT security platforms like Nozomi Guardian — so IT, OT/ICS, IoT, and cloud sit under one view rather than separate tools.

    04Can it actually stop an attack, or only alert?

    Active NDR performs automated response — blocking traffic, isolating systems, and coordinating with integrated tools — so containment happens in real time rather than waiting on manual action.

    05How does this relate to Trellix Network Security and IPS?

    The NDR Sensor evolves from the Network Security (NX) line, and IPS "NDR Ready" combines full intrusion prevention with NDR at up to 240 Gbps. Faltrox scopes which form factor fits your throughput and whether you need inline prevention alongside detection.

    Start an engagement

    Secure what’s next.

    Speak with the engineering team to define scope, walk through the methodology, and decide whether Faltrox is the right team to test and run your environment.

    Contact us